October 8, 2026 12:14 am

Preparing Data Breach Response under the Digital Personal Data Protection Act, 2023. A Simple Guide to Handling a Data Breach under India’s DPDP Act, 2023 

AUTHOR: Sristi Singh, City Academy Law College

1. Introduction: What Is a Data Breach and Why Does It Matter? 

The era of treating data breaches as merely an internal IT glitch is officially over in India’s digital landscape with the Digital Personal Data Protection Act, 2023 (DPDP Act) and its subsequent rules. Unlike some global frameworks, where certain low-risk breaches may not trigger mandatory regulatory notifications, India’s framework places significant emphasis on prompt breach reporting. Organisations must therefore treat personal data breaches as legal and compliance matters, not merely technical incidents. 

According to Section 2(u) of the Act, a “personal data breach” means any unauthorised processing of personal data or accidental disclosure, acquisition, sharing, use, alteration, destruction, or loss of access to personal data that compromises the confidentiality, integrity, or availability of personal data. 

Section 8(6) imposes an obligation on the Data Fiduciary to intimate a personal data breach to the Data Protection Board of India and affected Data Principals in accordance with the prescribed requirements. Section 8(5) requires the Data Fiduciary to implement appropriate technical and organisational measures to ensure effective observance of the provisions of the Act. Non-compliance can attract significant financial penalties under the Schedule to the Act. 

2. The Dual-Clock Dilemma: Navigating CERT-In and DPBI Timelines 

When a breach occurs, a company does not have the luxury of waiting. Businesses may have to comply simultaneously with requirements under the DPDP framework and the directions issued by the Indian Computer Emergency Response Team (CERT-In). This is often described as a “dual-clock” compliance challenge because different reporting obligations may arise from the same incident. 

The 6-Hour Cyber-Incident Clock — CERT-In 

For specified cyber-security incidents, including certain serious cyber incidents, the CERT-In Directions require reporting to CERT-In within six hours of noticing such incidents or being brought to notice of them. This requirement concerns

cyber-security incident reporting and operates separately from personal data breach obligations. 

The Personal Data Breach Reporting Clock — DPDP Framework 

Where a cyber incident also results in a personal data breach, the organisation must comply with the applicable DPDP breach-intimation requirements. The organisation should therefore begin its legal and privacy assessment immediately rather than waiting for the technical investigation to finish. 

In practice, the IT/security team should address containment and cyber-incident reporting, while the legal, privacy and compliance teams simultaneously assess the personal data breach and prepare the required notifications. 

3. Defining “Hour Zero”: When Does the Clock Actually Start? 

A key question is, when should the organisation start counting time for breach reporting? The practical trigger is when the organisation becomes aware of the breach or is informed of it, rather than the moment when an attacker may have first entered the system. 

The Awareness Rule 

The organisation should record the exact time at which it becomes aware of the personal data breach. This should be treated as “Hour Zero” for purposes of organising the response and calculating applicable reporting deadlines. 

• Personal Alert: If a junior IT employee notices an unusual data download at 2:00 AM and the organisation is thereby alerted to a suspected breach, the incident-response clock should begin from that point. It should not be postponed until a senior manager reaches the office. 

• Third-Party Vendors: Many organisations share personal data with external vendors, such as cloud-storage providers or delivery partners. If a breach occurs within a vendor environment and the vendor informs the organisation, the organisation should promptly record the time of notification and begin its breach-response process. 

4. The Four-Phase Operational Incident Response Playbook 

When a personal data breach occurs, the organisation should not panic. A structured, step-by-step action plan helps protect personal data while ensuring that legal and regulatory deadlines are met. The response can be divided into four practical phases.

Phase 1: Rapid Triage and Containment (Hours 0-2) 

• Stop the bleeding: Immediately isolate compromised servers or systems from the network and revoke exposed API keys and access tokens where appropriate. 

• Force password resets: Change credentials for administrative accounts that may have been exposed and implement additional authentication controls where necessary. 

• Preserve digital evidence: Secure system logs, server records and other relevant forensic evidence in their original form so investigators can determine how the incident occurred. 

Phase 2: Data Mapping and Scoping (Hours 2-12) 

• Identify the affected persons: Cross-reference affected systems with the organisation’s databases to determine whose personal data may have been compromised. 

• Classify the affected data: Determine whether the incident involved basic identifiers, financial information, health-related information, children’s personal data, or other sensitive or high-risk information. 

• Assess the scale: Determine the number of affected Data Principals, the categories of personal data involved, and the likely consequences of the breach. 

Phase 3: Root-Cause Investigation and Drafting (Hours 12-36) 

• Find the loopholes: Determine how the attacker gained access, such as through a weak password, phishing attack, stolen credentials, or system misconfiguration. 

• Prepare the official report: Draft the required notification to the Data Protection Board of India, containing the information required under the applicable rules and directions. 

• Prepare the user alert: Draft a clear and simple notice for affected customers explaining what happened, what information may have been affected, what the organisation has done, and what protective steps users should take. 

Phase 4: Internal Sign-Off and Simultaneous Reporting (Hours 36-72) 

• Obtain legal approval: Send the draft notification to the Data Protection Officer, where applicable, and legal or compliance advisers for review. 

• Obtain executive sign-off: Present the final response to the appropriate senior management or authorised decision-makers for immediate approval.

• Submit notifications: File the required notification with the competent authority and communicate with affected Data Principals within the applicable statutory timeline and in the prescribed manner. 

5. Activating the Cross-Functional Data Breach Response Team 

When a data breach occurs, relying only on the IT department to handle the crisis is a major error. Organisations should establish a pre-appointed, cross-functional Data Breach Response Team comprising representatives from relevant departments. This structure enables rapid decision-making and legally sound communication under pressure. 

Legal and Compliance Lead 

The legal and compliance lead assesses legal exposure, regulatory obligations and potential liabilities and reviews external communications. The team should also ensure that evidence and communications are handled appropriately and that legal advice is documented. 

Chief Information Security Officer / Senior IT Head 

The technical lead manages containment, eradication and recovery. Key responsibilities include blocking threats, closing system vulnerabilities, securing affected systems and preserving digital forensic evidence. 

Data Protection Officer / Privacy Lead 

Where applicable, the Data Protection Officer or privacy lead coordinates privacy compliance, compiles the incident report, manages required breach notifications and handles interactions with the relevant data-protection authority. 

Public Relations / Communications Representative 

The communications representative ensures that employees and the public receive accurate and consistent information. The representative should prevent the circulation of unverified rumours while coordinating transparent and empathetic communication with affected Data Principals. 

6. Conclusion: Building a Culture of Continuous Privacy Readiness 

Under the DPDP Act, having a strong data-breach response plan is essential for responsible data governance. Organisations should not create policies merely on paper and then ignore them. They should conduct regular table-top drills and

simulated breach exercises so that every department—from IT and legal to privacy and corporate communications—knows exactly how to respond without losing valuable time. 

If a data breach occurs, attempting to hide the incident or delaying the response can increase regulatory and reputational risk. A better approach is to take swift technical action, preserve evidence, assess the scope of the breach, make the required regulatory notifications on time, and communicate transparently with affected users. Ultimately, treating privacy readiness not merely as a regulatory burden but as an opportunity to demonstrate reliability can help protect an organisation’s reputation and maintain customer trust over the long term.

Disclaimer: This article is published for educational and informational purposes only and does not constitute legal advice, legal opinion, or professional counsel. It does not create a lawyer–client relationship. All views and opinions expressed are solely those of the author and represent their independent analysis. Times Law does not endorse, verify, or assume responsibility for the author’s views or conclusions. While editorial standards are maintained, Times Law, the author, and the publisher disclaim all liability for any errors, omissions, or consequences arising from reliance on this content. Readers are advised to consult a qualified legal professional before acting on any information herein. Use of this article is at the reader’s own risk.